Privacy policy
Last updated 15 September 2026
Who we are
Able Style Ltd. is the controller responsible for the personal information described in this policy. We are registered in England and Wales under company number 10622553, with a registered office at 20-22 Wenlock Road, London, England, N1 7GU. You can contact us at able@able.style.
This policy applies when you use the Able.Style website, mobile applications, and related services.
Information we collect
The information we collect depends on the features you choose to use. It may include:
- Account and profile information, such as your email address, username, authentication provider, profile information, preferences, and account settings.
- Content and activity, such as photos and descriptions you submit, wardrobe and outfit information, tagged styles, likes or dislikes, follows, and whether content is public or private.
- Communications you send when you contact us for support, feedback, or another request.
- Technical and security information, such as IP address, browser or device type, operating system, language, timestamps, authentication and App Check information, and diagnostic or security logs.
- Optional Analytics and website performance information, described separately below.
You can browse public parts of the website without creating an account. An account is required for features that save, personalise, synchronise, or publish information for you.
Safety reports and moderation
Signed-in registered users, existing anonymous users, and people who are not signed in may report a public post. A report includes the selected category and any optional supporting text you provide. Registered reports are linked to the reporting account so the report can be shown and withdrawn. Anonymous and signed-out reports are not added to a later account and can only hide the post using a versioned list stored on that browser or app installation; clearing site data or uninstalling the app may remove that local hiding preference.
To deter duplicate or abusive anonymous reports without retaining a raw network address, we transform the request IP address using a secret-keyed, date-specific pseudonymous hash. We use the current and previous daily hashes for deduplication and a rolling 24-hour reporting limit. We do not store the raw IP for this purpose, and remove the temporary hash after 48 hours.
Authorised moderators can access reports, optional text, aggregate cases, and related content to protect users, enforce our Community Guidelines, and handle legal or safety concerns. Our lawful basis is our legitimate interests in operating a safe service, preventing misuse, and protecting users and third parties, balanced against the rights of affected people. Urgent categories are prioritised. Report-category totals, without reporter identifiers or optional report text, may be sent to our support team through Postmark, which processes email delivery information on our behalf. We keep withdrawn reports, resolved cases, report evidence, and audit events for up to 12 months, then strip expired evidence. A minimal active registered hide relationship may remain until withdrawal, account deletion, or permanent content deletion.
Deleting a registered account removes its active report preferences and anonymises retained audit events. Anonymous local hiding data is controlled from the relevant browser or installation. Your access, objection, erasure, restriction, and complaint rights described below also apply to report information, subject to lawful safety, legal-claim, and audit-retention exceptions.
User blocking
Registered users may block another account and select one or more reasons, with an optional comment. We keep each block and unblock cycle, its dates and current state, and a minimal pairwise visibility record used to hide content, prevent following, and exclude outfit suggestions. Blocking removes follows in both directions, does not restore them after unblocking, and is not disclosed to the blocked account.
Authorised moderators can access block records, selected reasons, optional comments, review status, and every non-private post by the blocked account. A safety-related block sends the participant identifiers and usernames, reason labels, optional comment, priority, due time, and a secure review link to our support team through Postmark. Preference-only blocks do not send an email. Child-safety and self-harm or illegal-activity selections are prioritised for review within 24 hours; other safety selections within 72 hours.
Inactive block history is normally kept while both participant accounts exist and is removed on account deletion. Where an authorised moderator confirms illegal-content evidence and our approved legal procedure applies, a legal hold may preserve the block and moderator review and capture the blocked account's email in the moderator-only record. Releasing the hold removes that captured email and completes deferred deletion. Legal holds remain disabled until their retention, access, evidence, external-reporting, and release procedure has completed legal and privacy review.
Location information
If you enable a location-based feature, we may receive your device's latitude and longitude to retrieve local weather forecasts and personalise weather-based outfit suggestions. This location is used for the feature you requested and is not sent as a custom Google Analytics event parameter. If you allow Analytics, Google may infer an approximate location from ordinary device or network information. You can control precise-location access in your browser or device settings.
How and why we use information
We use personal information for the following purposes and legal bases, where applicable:
- Providing the service and performing our contract with you, including authentication, storing your content and settings, synchronising your account, and delivering features you request.
- Our legitimate interests in securing, maintaining, troubleshooting, and improving the service, provided those interests are not overridden by your rights. This basis does not replace consent for the optional Google Analytics and website Performance Monitoring described below.
- Your consent for optional Google Analytics, website Performance Monitoring, and other features where we specifically ask for consent. You can withdraw consent at any time.
- Legal obligations, including responding to valid legal requests and protecting rights.
Cookies, app storage, and optional measurement
Essential storage
Essential browser or app storage supports security, sign-in, requested product features, and remembering your privacy choice. It remains active where necessary to provide the service. Your Analytics choice is stored locally with a notice version and update time. An invalid or outdated record is ignored; otherwise, the choice remains until you change it or local app or browser data is removed. In the mobile app, your choice is stored with the app and may be restored from a device backup.
Google Analytics
Google Analytics is optional and is off until you select Allow analytics. Declining does not restrict your use of Able.Style. If allowed, we use Google Analytics to understand which screens and features are useful, measure successful product actions, and improve the service.
Depending on how you use Able.Style, Analytics may receive:
- controlled screen and product events, for example that an account was created, a sign-in succeeded, a search ran, content was opened, an item category was added to a wardrobe, an image was posted, or an outfit was logged;
- limited attributes about those actions, such as sign-in method, search area, whether filters were used, broad wardrobe category, or whether a post was private or intended as an outfit log;
- session statistics and browser, device, operating-system, app-version, language, and screen information;
- approximate location inferred by Google from network information, and a random browser client identifier or mobile app-instance identifier; and
- your pseudonymous user ID when you use a consenting, non-anonymous signed-in account. We use it to associate your Analytics activity across sessions and across the web, Android, and iOS applications.
We do not intentionally send names, email addresses, phone numbers, usernames, images, wardrobe contents, item or content IDs, raw URLs, URL query parameters, search text, precise location, advertising identifiers, or free text to Google Analytics. Web page-location, referrer, and title values are replaced with controlled, non-identifying values before events are sent.
On the web, Google Analytics uses first-party cookies named _ga and _ga_<stream-id> to distinguish users and sessions. Their default maximum lifetime is two years, although browsers may impose a shorter limit. In the mobile applications, Google Analytics uses a random app-instance identifier. Able.Style disables advertising storage, advertising user data, personalised advertising, and collection of mobile advertising identifiers for Analytics.
Google processes this information to provide, secure, and maintain Analytics for us under its applicable data-processing terms. Read how Google uses information from sites or apps that use its services .
Google Analytics user-level and event-level data is configured to be retained for 14 months, without resetting that period when a user becomes active again. Google explains that this setting does not control the retention of its standard aggregated reports.
Firebase Performance Monitoring on the website
On the website, selecting Allow analytics also starts Firebase Performance Monitoring. It is not initialised before you allow it. We use it to identify slow page loads and network requests so that we can improve the website's reliability and speed.
Firebase Performance Monitoring may receive:
- page URLs and page-load timing;
- network-request URLs without URL parameters or payload content, together with response codes, response times, and payload sizes;
- a Firebase installation ID and random session ID, plus browser, device, operating-system, language, application-version, and network information; and
- country inferred from the request IP address.
Google states that Performance Monitoring keeps IP-associated events for 30 days and keeps installation-associated and de-identified performance data for 60 days before beginning removal from live and backup systems. See Firebase privacy and security information .
You can allow or withdraw optional Analytics and website Performance Monitoring at any time in Privacy settings. Withdrawal closes Able.Style's event gate immediately, disables future collection, clears the Analytics User-ID, resets local Analytics state where supported, and disables website performance instrumentation. It does not affect the lawfulness of processing before withdrawal or automatically delete information already retained by Google. You may contact us if you want us to assess a request concerning retained optional-measurement data.
When we share information
We may share personal information only as needed in the following circumstances:
- with service providers that host, secure, support, or operate Able.Style, including cloud-hosting providers; and, only after consent, with Google Analytics and Firebase Performance Monitoring;
- with other people when you deliberately make content public or use a sharing feature;
- when required by law or necessary to establish, exercise, or defend legal rights; or
- as part of a merger, financing, reorganisation, or sale of all or part of the business, subject to appropriate confidentiality and legal requirements.
We do not sell personal information or use Google Analytics for third-party advertising.
International transfers
Some service providers, including Google, may process information outside the United Kingdom or European Economic Area. Where data-protection law restricts a transfer, we use an applicable adequacy decision or contractual and organisational safeguards under the provider's data-processing terms. Contact us if you would like more information about the safeguards relevant to your information.
How long we keep information
We keep account and product information for as long as it is needed to provide the service, meet legal or security requirements, resolve disputes, and enforce agreements. The period depends on the type of information, why it is needed, and whether you delete it or close your account. Backup copies and records required for legal or security reasons may remain for a limited additional period. The separate Google Analytics and Firebase Performance Monitoring periods are described above.
Security
We use technical and organisational measures intended to protect personal information against loss, misuse, and unauthorised access, alteration, or disclosure. No internet service can guarantee absolute security.
Your choices and rights
Depending on the law that applies and the circumstances, you may have rights to access, correct, erase, restrict, or receive a copy of your personal information, and to object to certain processing. Where processing is based on consent, you can withdraw that consent at any time. To exercise a right or make a privacy complaint, email able@able.style. We may need to verify your identity and may retain information where the law permits or requires it.
You may also complain to the UK Information Commissioner's Office through ico.org.uk, or to the data-protection authority where you live or work if another authority is applicable.
Changes to this policy
We may update this policy as the service or applicable requirements change. We will update the date above and provide an appropriate notice for material changes. If we materially change the purposes, recipients, identifiers, or data categories used for optional measurement, we will treat the existing notice as outdated and ask you to make a new choice where required.
Contact
Able Style Ltd.20-22 Wenlock Road
London, England, N1 7GU
Email: able@able.style